Forms में CSRF Protection
In this page:
<form method="post">
{% csrf_token %}
<!-- form fields -->
<button type="submit">Submit</button>
</form>
CSRF Protection क्यों मौजूद है
इसके बिना, एक malicious site एक logged-in user के browser को आपके app को उनकी जानकारी के बिना एक form submit करने के लिए trick कर सकती है।
उदाहरण: Why CSRF Protection Exists
Without it, a malicious site could trick a logged-in user's browser into submitting a form to your app without their knowledge.
<form method="post">
{% csrf_token %}
{{ form.as_p }}
<button type="submit">Save</button>
</form>
{# Django-only code -- models.py/views.py/urls.py/settings.py
snippets, or template markup using Django template tags/variables
-- can't run standalone via Judge0 or the browser preview, since
it needs a real Django project. Only this course's pure-Python
examples (example_lang == 'python', no Django imports) are
actually runnable, so those still get the button below. #}
Token के बिना क्या होता है
एक POST request जिसमें csrf token missing हो, Django के middleware द्वारा एक 403 Forbidden response के साथ reject कर दी जाती है, आपके view के चलने से पहले ही।
उदाहरण: What Happens Without the Token
A POST request missing the csrf token is rejected by Django's middleware with a 403 Forbidden response, before your view even runs.
# settings.py
MIDDLEWARE = [
# ...
'django.middleware.csrf.CsrfViewMiddleware',
# ...
]
{# Django-only code -- models.py/views.py/urls.py/settings.py
snippets, or template markup using Django template tags/variables
-- can't run standalone via Judge0 or the browser preview, since
it needs a real Django project. Only this course's pure-Python
examples (example_lang == 'python', no Django imports) are
actually runnable, so those still get the button below. #}
AJAX Requests में CSRF Token
JavaScript-driven POST requests के लिए, token को cookie या एक hidden input से पढ़ें और इसे X-CSRFToken header के रूप में भेजें।
उदाहरण: CSRF Token in AJAX Requests
For JavaScript-driven POST requests, read the token from the cookie or a hidden input and send it as the X-CSRFToken header.
<script>
fetch('/save/', {
method: 'POST',
headers: {'X-CSRFToken': document.querySelector('[name=csrfmiddlewaretoken]').value},
body: new FormData(document.querySelector('form'))
});
</script>
{# Django-only code -- models.py/views.py/urls.py/settings.py
snippets, or template markup using Django template tags/variables
-- can't run standalone via Judge0 or the browser preview, since
it needs a real Django project. Only this course's pure-Python
examples (example_lang == 'python', no Django imports) are
actually runnable, so those still get the button below. #}
- एक POST form से
{% csrf_token %}छोड़ देना, जिसके कारण Django submission को 403 Forbidden error के साथ reject कर देता है। - Error को fix करने के लिए globally CSRF protection disable करना, missing token tag जोड़ने के बजाय।
- यह भूल जाना कि AJAX POST requests को भी CSRF token एक header के रूप में भेजना चाहिए, सिर्फ template forms में नहीं।
- Django का
CsrfViewMiddlewareउन POST requests को reject करता है जिनमें एक valid CSRF token शामिल नहीं होता। - हर template form जो POST से submit होता है उसमें
<form>tag के अंदर{% csrf_token %}शामिल होना चाहिए। - Token per session unique है, जो दूसरी sites को आपके app के लिए requests forge करने से रोकता है।
Chapter Quiz — Complete all 11 topics to unlock
0/11 topics done
Complete these topics first: